Sceawere

Vulnerability Detail

CVE-2026-70991UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce Guided Search Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-08-18T21:17:58.083Z",
  "pubdate": "2026-08-18T21:17:58.083Z",
  "executiveSummary": "An unauthenticated information disclosure vulnerability affects the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. This flaw allows an attacker with local infrastructure logon access to compromise the targeted software and achieve unauthorized access to critical or complete data accessible by the application. The vulnerability yields a CVSS 3.1 Base Score of 6.3, with a vector indicating local attack vector, low attack complexity, no privileges required, and required user interaction resulting in a scope change with high confidentiality impacts.\nThe risk implications are significant due to the potential exposure of sensitive data managed within the Oracle Commerce ecosystem. Although the vulnerability resides within Oracle Commerce Guided Search / Oracle Commerce Experience Manager, successful exploitation can result in a scope change that impacts additional associated products. Attack prerequisites dictate that the attacker must already possess logon access to the underlying infrastructure hosting the application and that a secondary user must perform unintended actions requiring human interaction during the exploitation phase.",
  "technicalDetails": "The vulnerability exists within the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The root cause stems from improper handling of data confidentiality and access control boundaries within the infrastructure layer where the affected product executes. The vulnerability manifests with a CVSS 3.1 vector of AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N, indicating that network exposure is absent in favor of a local attack vector (AV:L), requiring local infrastructure access.\nExploitation of this vulnerability requires an attacker to have prior logon access to the infrastructure hosting the Oracle Commerce Guided Search / Oracle Commerce Experience Manager deployment. Despite requiring local access, the attack complexity is low (AC:L) and requires no direct authentication privileges (PR:N) against the specific application component itself. However, successful exploitation mandates human interaction (UI:R) from an individual other than the attacker, such as an authenticated user or administrator executing a routine task that inadvertently triggers the attack payload or workflow.\nThe attack flow proceeds as follows: First, the unauthenticated attacker leverages their existing local logon access to the target infrastructure to position malicious artifacts or configure interactions related to the Content Acquisition System. Second, the attacker induces a state requiring human interaction from a secondary user interacting with the Oracle Commerce Guided Search / Oracle Commerce Experience Manager environment. Third, upon execution and user interaction, the security context crosses boundaries due to the scope change (S:C) characteristic of the vulnerability. Finally, the payload triggers unauthorized access to critical data or complete access to all data accessible by Oracle Commerce Guided Search / Oracle Commerce Experience Manager, resulting in a high confidentiality impact (C:H) with no direct integrity or availability disruption."
}
CVE-2026-70991: Oracle Commerce Guided Search Information Disclosure (MEDIUM Severity, CVSS: 6.3) - Sceawere